Junglewise Threat Intelligence

CVE-2026-86488: JetBrains YouTrack insecure direct object reference in watchRules and issueListConfig

CVE-2026-86488 · Severity: medium · CVSS 6.5 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is an issue tracking and project management platform used by development teams to manage work and collaborate on projects. An insecure direct object reference vulnerability in the watchRules and issueListConfig endpoints allows attackers to access private saved searches belonging to other users, potentially exposing sensitive project information and search criteria that organizations intended to keep confidential.

Technical details

The vulnerability is an insecure direct object reference (IDOR) affecting the watchRules and issueListConfig API endpoints in YouTrack. By manipulating object identifiers in requests to these endpoints, an authenticated attacker can enumerate and access private saved searches belonging to other users without proper authorization checks. The vulnerability requires network access to the YouTrack instance and an active user account. The flaw was fixed in version 2026.2.18634 and later, and patches are available from JetBrains.

Affected products

  • JetBrains YouTrack before 2026.2.18634

Timeline

  • 2026-09-07: disclosed

References

Related threats